All Breaches
December 10, 2025 Verified Sensitive Record Healthcare

Erie Family Health Centers 2025 Data Breach

The Erie Family Health Centers 2025 data breach involved an unauthorized third party accessing systems of the Chicago-based health-center network on December 10, 2025 and maintaining access through January 27, 2026. The current breach record maintained by the US Department of Health and Human Services Office for Civil Rights shows that 570,000 people were affected.

Erie is a network of health centers providing primary medical, dental, and behavioral healthcare regardless of ability to pay. The event involved identity, contact, financial, account, biometric, medical, and insurance information; file contents varied by person. LeakData imports no personal records and importedRecordCount is zero.

How Was the Breach Confirmed?

Erie identified potentially unauthorized access to certain network systems on January 27, 2026 and opened an investigation with outside specialists. The forensic review confirmed that its network was subject to unauthorized access from December 10 through January 27. The organization reported the event to law enforcement, secured the systems, and reviewed data that may have been affected.

HHS OCR lists the event as a Hacking/IT Incident, the information location as Network Server, and the entity type as Healthcare Provider. HIPAA Journal compared the official notice with the federal record and corroborated the access window, 570,000-person scope, and file categories. Because the sources do not definitively establish exfiltration, this entry does not describe data theft as confirmed.

What Was the Access and Notification Timeline?

The breachDate field uses December 10, 2025, the first day of access established by the forensic investigation. The unauthorized party could remain in the network for about seven weeks, and Erie identified and ended the access on January 27. The discovery date differs from the start date, and the year in the title follows the initial access in 2025.

After reviewing file contents, the organization began mailing notices to affected people. The HHS row carries a March 27, 2026 submission date; HIPAA Journal published the federal total and disclosed categories in May. Erie said it strengthened network security to help prevent similar events and worked with law enforcement during the investigation.

What Identity and Contact Information Was Affected?

Potential identity fields included names, physical addresses, telephone numbers, email addresses, and dates of birth. More sensitive identifiers included Social security numbers, driver's license or state identification numbers, taxpayer identification numbers, and passport numbers. The disclosure did not say every category appeared for every person, so the list does not guarantee any individual's scope.

Alone or in combination, these fields can support fraudulent account opening, tax fraud, and targeted phishing. Combining contact details with medical context may make a false message impersonating a healthcare organization more convincing. The sources do not identify a threat group that claimed responsibility for the event.

What Financial, Account, and Biometric Data Was Involved?

Financial-account information and payment-card information were potentially involved. Online-account credentials, digital signatures, and biometric data were also among the categories that could have been present in affected files. The sources do not disclose the format or authentication detail of each class, so LeakData does not infer a password type, account number, or biometric subtype.

Passwords can be changed, while digital signatures and biometric characteristics may present longer-lived risks. People whose notice includes payment-card or financial-account information should report unfamiliar transactions promptly; those with online credentials involved should make passwords unique and enable multifactor authentication. These precautions do not mean every victim had all of those fields.

What Health and Insurance Information Was Affected?

The medical scope included treatment or diagnosis information, prescription information, dates of service, patient and encounter identifiers, provider names, patient account numbers, and medical record numbers. Medicare or Medicaid numbers, health-insurance information, and treatment-cost information were also disclosed categories. Such data can create medical-identity-theft, false-claim, and privacy risks.

pwnCount and totalRecords use the current HHS OCR regulatory total of 570,000 people. That value is not split among data classes or applied separately to every field. The organization emphasizes that contents varied by person; LeakData does not calculate unreported subgroup counts or present a potential field as a confirmed individual exposure.

What Should Affected People Do?

Erie offered affected people complimentary credit monitoring and identity-protection services and established a dedicated call center for questions. Notice recipients should follow the enrollment instructions in their letter, inspect credit reports and financial-account and payment-card activity, and consider a fraud alert or security freeze when a Social Security number is involved.

People should also check health-insurance explanations, prescription histories, and patient accounts for unfamiliar services, providers, costs, or claims. Unexpected payment, password, or identity-verification requests made in Erie's name should be confirmed through a known official channel. LeakData does not host stolen files; it documents the verified incident scope and practical follow-up steps.

570 Thousand
Affected Accounts
25
Data Types
High
Severity
Yes
Verification

Exposed Data Types

25
Names
Physical addresses
Telephone numbers
Email addresses
Dates of birth
Social security numbers
Driver’s license and state id numbers
Taxpayer identification numbers
Passport numbers
Financial account information
Payment card information
Online account credentials
Digital signatures
Biometric data
Medical treatment and diagnosis information
Prescription information
Dates of service
Patient IDs
Encounter ids
Provider names
Patient account numbers
Medical record numbers
Medicare and medicaid numbers
Health insurance information
Treatment cost information

Additional Information

Added DateJuly 27, 2026
Breach DateDecember 10, 2025
Domaineriefamilyhealth.org
SourceConfirmed unauthorized network access involving files containing personal and protected health information
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information